ERROR_UNTRUSTED_MOUNT_POINT [DirReaderPlus] on cross-drive directory junctions (v14.x)

Get help for specific problems
Posts: 4
Joined: 17 Aug 2026

Sir.V.007

Hi Zenju,

Following the recent v14 updates, FreeFileSync fails during scans with the following error:
ERROR_UNTRUSTED_MOUNT_POINT: The path cannot be traversed because it contains an untrusted mount point. [DirReaderPlus]

Environment & Setup:

OS: Windows 11 Pro

Setup: My local music library resides on D:\Music. Due to disk space constraints, higher-resolution subfolders (e.g., 01 - Hi-Res [Over 192kHz...], 02 - Hi-Res [Up to DSD·128]) etc. are directory junctions/symlinks (mklink /J) pointing directly to a secondary physical drive (S:\Music\...). I currently have 9 sync sessions and there are 4 junctions within D:\Music to another drive on the same host laptop. I ran out of space on my 2TB M.2 that has D:\Music so had to manage with junctions to volume on my other 2TB M.2 to avoid making changes to how my music library is managed & sync'd to my Roon library as well as network & storage devices I replicate to. This allows my playlists to be managed across each device.

Sync Mode: Symlinks are set to Follow so that audio files on S:\ are synced to network endpoints (ROCK, streamer endpoints, DAP storage, etc.).

Issue:
In FreeFileSync v13.7, directory traversal across these cross-drive junctions in Follow mode worked seamlessly. Starting in v14, DirReaderPlus surfaces Windows Error 448 (ERROR_UNTRUSTED_MOUNT_POINT) and aborts the sync entirely unless FFS is explicitly executed with elevated Administrator privileges.

Changing link handling to Direct is not an option as it syncs the link pointer instead of the actual target files, breaking sync configurations across all devices.

Feature Request / Fix:
Could FFS either gracefully handle/bypass Windows Process Redirection Trust Policy checks for user-created local junctions, or provide a global setting/toggle trust setting for each mount in the sync settings to allow traversal of trusted local mount points without requiring full Administrator elevation?

Thanks!
Posts: 10
Joined: 1 Jul 2020

Ryamada

Same issue, and same request.

This caught up with me on the automated upgrade today (v14.11)
For me it's a showstopper, so I'd appreciate a fix...

For now rolling back... hopefully to the nearest good version (I am not sure which version I upgraded from). And unfortunately I also have to downgrade to the non-donation version too it seems...
User avatar
Site Admin
Posts: 7532
Joined: 9 Dec 2007

Zenju

"RedirectionGuard" is a new Windows 11 default setting apparently? I'm assuming ERROR_UNTRUSTED_MOUNT_POINT also occurs with previous FFS versions?
User avatar
Site Admin
Posts: 7532
Joined: 9 Dec 2007

Zenju

Posts: 10
Joined: 1 Jul 2020

Ryamada

Hi Zenju,

Thanks for the quick turnaround. The beta solves the issue for me!

(to be perfectly clear I ended up not rolling back to a previous version and instead ran 14.11 as Administrator, so I can't say for sure whether the issue was triggered by FFS v14+ or the latest Windows update - I had both happen on my PC at about the same time).
Posts: 4
Joined: 17 Aug 2026

Sir.V.007

"RedirectionGuard" is a new Windows 11 default setting apparently? I'm assuming ERROR_UNTRUSTED_MOUNT_POINT also occurs with previous FFS versions? Zenju, 18 Aug 2026, 13:42
Morning Zenju,

Yes correct, I set the exe ruin as admin for all users & forgot about it until the lastest update which reset it, so i had to do it again. My user has admin rights on Win11 Pro 25H2 host so setting the exe as admin seems a little too high with privileged access to me.

Cheers
V/-
Posts: 4
Joined: 17 Aug 2026

Sir.V.007

Thanks Zenju,

I see that modified date of the FreeFileSync.exe doesn't change with beta update, it was only post a windows restart after manually removing the run as administrator setting for all users did the admin icon get removed.

With initial FFS tests I've not detected any issues, I'll let you know if there are. Seems stable.

Appreciate the quick turn around Zenju, thanks.

Cheers
V/-
Posts: 4
Joined: 17 Aug 2026

Sir.V.007

I've been doing some reading on Redirection Guard, it would seem that setting a trust flag can be exploited if a malicious user updates the junction to point to a system folder, is it feasible to present juntions (source & target) on the source sync path to validate before sync as a more secure option rather than outright disable it? That way before each sync the user can verify that the sumbolic links or junctions are valid and can continue. Just a thought.

https://www.microsoft.com/en-us/msrc/blog/2025/06/redirectionguard-mitigating-unsafe-junction-traversal-in-windows?msockid=0cfbbb05b18b64b405c3ac01b06665d2